do i need to set guards for passport routes?

Viewed 43

I am confused after a lot of reading, I think that I have understood less than before!

I have my passport configured on Laravel 8:

'api' => [
    'driver' => 'passport',
    'provider' => 'users',
],

So I am serving via these routes: login, logout and registration.

Route::post('/register', [AuthController::class, 'register']);
Route::post('/login', [AuthController::class, 'login']);
Route::post('/logout', [AuthController::class, 'logout']);

And the AuthController provides the methods and almost works!

My questions are:

  • If I add a guard to logout this will not work. So is it unnecessary or am I with wrong logic? Or is it correct as I've written?
  • Do I need to manage refresh tokens? And if yes, should the route be guarded? Or what have I to do when the token expires?

I have tried to add a method:

public function refresh() {
    return $this->createNewToken(auth()->refresh());
}

But this gives me back this error:

BadMethodCallException: Method Illuminate\Auth\RequestGuard::refresh does not exist. in file /home/natty/workspace/sportIndexBackEnd/vendor/laravel/framework/src/Illuminate/Macroable/Traits/Macroable.php on line 103

0 Answers
Related